Buffer overflow in tftp-hpa before 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the utimeout option.
http://www.securityfocus.com/bid/48411
http://www.pre-cert.de/advisories/PRE-SA-2011-05.txt
http://www.openwall.com/lists/oss-security/2011/06/13/11